Cisco Catalyst Center Vulnerability Let Attackers Escalate Priveleges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A serious security flaw in Cisco Catalyst Center Virtual Appliance has been discovered that allows attackers with low-level access to gain full administrator control over affected systems. The vulnerability, tracked …

PoC Exploit Tool Released for FortiWeb WAF Vulnerability Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept (PoC) exploit tool for CVE-2025-64446 has been publicly released on GitHub. This vulnerability, affecting FortiWeb devices from Fortinet, involves a critical path traversal flaw that has already been …

Critical pgAdmin4 Vulnerability Lets Attackers Execute Remote Code on Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe remote code execution (RCE) flaw has been uncovered in pgAdmin4, the popular open-source interface for PostgreSQL databases. Dubbed CVE-2025-12762, the vulnerability affects versions up to 9.9 and could …

RONINGLOADER Weaponizes Signed Drivers to Disable Defender and Evade EDR Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new threat targeting Chinese users has appeared with a dangerous ability to shut down security tools. RONINGLOADER, a multi-stage loader spreading a modified version of the gh0st RAT, uses …

Hackers are Weaponizing Invoices to Deliver XWorm That Steals Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Attackers are using fake invoice emails to spread XWorm, a remote-access trojan that quietly steals login credentials, passwords, and sensitive files from infected computers. When a user opens the attached …

First Large-scale Cyberattack Using AI Tools With Minimal Human Input

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chinese government-backed hackers used Anthropic’s Claude Code tool to carry out advanced spying on about thirty targets worldwide, successfully breaking into several major organizations. The first documented large-scale cyberattack executed …

Highly Sophisticated macOS DigitStealer Employs Multi-Stage Attacks to Evade detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware family targeting macOS systems has emerged with advanced detection evasion techniques and multi-stage attack chains. Named DigitStealer, this information stealer uses multiple payloads to steal sensitive data …

Formbook Malware Delivered Using Weaponized Zip Files and Multiple Scripts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of Formbook malware attacks has appeared, using weaponized ZIP archives and multiple script layers to bypass security controls. The attacks begin with phishing emails containing ZIP files …

A Multi-Stage Phishing Kit Using Telegram to Harvest Credentials and Bypass Automated Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phishing attacks continue to be one of the most persistent threats targeting organizations worldwide. Cybercriminals are constantly improving their methods to steal sensitive information, and a recently discovered phishing kit …

Akira Ransomware Targets Over 250 Organizations, Extracts $42 Million in Ransom Payments – New CISA Report

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new advisory from the Cybersecurity and Infrastructure Security Agency reveals that Akira ransomware has become one of the most active threats targeting businesses worldwide. Since March 2023, this ransomware …